Jenkins Warnings Next Generation Plugin 9.10.2 and earlier does not restrict the name of a file when configuring custom ID, allowing attackers with Item/Configure permission to write and read specific files with a hard-coded suffix on the Jenkins controller file system.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| io.jenkins.plugins:warnings-ng(Maven) | 9.8.0 | 9.10.3 | N/A |
| io.jenkins.plugins:warnings-ng(Maven) | 9.6.0 | 9.7.1 | N/A |
| io.jenkins.plugins:warnings-ng(Maven) | 9.1.0 | 9.5.2 | N/A |
| io.jenkins.plugins:warnings-ng(Maven) | 0 | 9.0.2 | N/A |
CVSS Metrics